# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=85

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 86

---

## [Decoding json fields properly with filebeat](https://discuss.elastic.co/t/decoding-json-fields-properly-with-filebeat/307596)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 3\
**Last updated:** [June 26, 2022, 3:57am UTC](https://discuss.elastic.co/t/decoding-json-fields-properly-with-filebeat/307596 "2022-06-26T03:57:40Z")

</div>

Hi Team, I am trying to parse modsec\_audit logs with filebeat in json format. However those are not being parsed correctly. Here is the original log. {"transaction":{"client\_ip":"66.249.66.154","time\_stamp":"Mon Jun 2…

---

## [Filebeat use too many cpu times to gzip](https://discuss.elastic.co/t/filebeat-use-too-many-cpu-times-to-gzip/308163)

<div class="topic-metadata">

**Author:** [@MrLiukang](https://discuss.elastic.co/u/MrLiukang)\
**Replies:** 0\
**Last updated:** [June 25, 2022, 12:10pm UTC](https://discuss.elastic.co/t/filebeat-use-too-many-cpu-times-to-gzip/308163 "2022-06-25T12:10:24Z")

</div>

hey guys. I found my filebeat send msg too slow,so I use two commands to profile filebeat, perf record -a -g -p xxx perf report -n --stdio the result show the filebeat use lots of cpu times to gzip msg? can we red…

---

## [Indentation error on filebeat conf](https://discuss.elastic.co/t/indentation-error-on-filebeat-conf/308033)

<div class="topic-metadata">

**Author:** [@Guillaume\_D](https://discuss.elastic.co/u/Guillaume_D)\
**Replies:** 4\
**Last updated:** [June 24, 2022, 4:58pm UTC](https://discuss.elastic.co/t/indentation-error-on-filebeat-conf/308033 "2022-06-24T16:58:55Z")

</div>

Hi, I want to do some basic process with filebeat on my logs but I have some indentations problemes I just don't know how to resolve. Here is the current stat of the conf file, input and output has been sensored but I a…

---

## [Filebeat setup (error loading template: failed to put data stream. no matching index template found for data stream)](https://discuss.elastic.co/t/filebeat-setup-error-loading-template-failed-to-put-data-stream-no-matching-index-template-found-for-data-stream/307789)

<div class="topic-metadata">

**Author:** [@ulisses](https://discuss.elastic.co/u/ulisses)\
**Replies:** 5\
**Last updated:** [June 24, 2022, 3:24pm UTC](https://discuss.elastic.co/t/filebeat-setup-error-loading-template-failed-to-put-data-stream-no-matching-index-template-found-for-data-stream/307789 "2022-06-24T15:24:31Z")

</div>

I'm running a dev environment to understand how i can use filebeat and elasticsearch to store our application logs but i can't make it work with custom configurations. I'm trying to change index name following this docu…

---

## [Where can I add actions to Auditbeat or Filebeat?](https://discuss.elastic.co/t/where-can-i-add-actions-to-auditbeat-or-filebeat/308081)

<div class="topic-metadata">

**Author:** [@Shadow\_CHN](https://discuss.elastic.co/u/Shadow_CHN)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 6:52am UTC](https://discuss.elastic.co/t/where-can-i-add-actions-to-auditbeat-or-filebeat/308081 "2022-06-24T06:52:19Z")

</div>

If the contents of event.action that Auditbeat already provided me doesn't enough, or I want to add a field which means event.action for the logs Filebeat collected. How can I make this happen? Also I want to know how m…

---

## [Question regarding using a logo](https://discuss.elastic.co/t/question-regarding-using-a-logo/308027)

<div class="topic-metadata">

**Author:** [@Marko\_Todoric](https://discuss.elastic.co/u/Marko_Todoric)\
**Replies:** 1\
**Last updated:** [June 24, 2022, 12:15am UTC](https://discuss.elastic.co/t/question-regarding-using-a-logo/308027 "2022-06-24T00:15:51Z")

</div>

Hello everyone I'm creating an addon for an open source project that would essentially be filebeat and will be used to ship logs to user self-hosted elasticsearch cluster/node so they can store and/or analyze logs. I wo…

---

## [Metricbeat error about scanning empty io.stat file](https://discuss.elastic.co/t/metricbeat-error-about-scanning-empty-io-stat-file/308063)

<div class="topic-metadata">

**Author:** [@matutter](https://discuss.elastic.co/u/matutter)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 11:53pm UTC](https://discuss.elastic.co/t/metricbeat-error-about-scanning-empty-io-stat-file/308063 "2022-06-23T23:53:52Z")

</div>

I'm deploying metricbeat and using the system and docker modules but keep getting an error message in my logs. My configs are below. The content of /hostfs/sys/fs/cgroup/io.stat on my system is nothing - it is an empty f…

---

## [Filebeat error: fail to execute the HTTP GET request: Get "https://172.30.169.50:5000/api/status": x509: certificate signed by unknown authority](https://discuss.elastic.co/t/filebeat-error-fail-to-execute-the-http-get-request-get-https-172-30-169-50-5000-api-status-x509-certificate-signed-by-unknown-authority/308057)

<div class="topic-metadata">

**Author:** [@gisellecarballo](https://discuss.elastic.co/u/gisellecarballo)\
**Replies:** 1\
**Last updated:** [June 23, 2022, 10:45pm UTC](https://discuss.elastic.co/t/filebeat-error-fail-to-execute-the-http-get-request-get-https-172-30-169-50-5000-api-status-x509-certificate-signed-by-unknown-authority/308057 "2022-06-23T22:45:21Z")

</div>

Hi Team, Anyone had an idea why I am getting this error while setting up filebeat. Thanks so much. \</\> Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://172.30.169.50:5000…

---

## [Update data in Elastic with Filebeats](https://discuss.elastic.co/t/update-data-in-elastic-with-filebeats/308019)

<div class="topic-metadata">

**Author:** [@Worlock](https://discuss.elastic.co/u/Worlock)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 1:48pm UTC](https://discuss.elastic.co/t/update-data-in-elastic-with-filebeats/308019 "2022-06-23T13:48:45Z")

</div>

I have some data from our Monitoring tool that is uploaded to Elastic with Filebeats. When the monitoring alert is closed, I get a new entry with "Resolution state: Closed" I would like to update the Resolution state in …

---

## [Awsfargate metricbeat module not working?](https://discuss.elastic.co/t/awsfargate-metricbeat-module-not-working/307990)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 1\
**Last updated:** [June 23, 2022, 1:59pm UTC](https://discuss.elastic.co/t/awsfargate-metricbeat-module-not-working/307990 "2022-06-23T13:59:20Z")

</div>

I've declared a metricbeat container in an AWS ECS task definition so that it runs as a "sidecar" container to my main application and uses the awsfargate module to index task stats (CPU, memory etc) into my monitoring c…

---

## [Office 365 Logs - Struggling to get data in](https://discuss.elastic.co/t/office-365-logs-struggling-to-get-data-in/308015)

<div class="topic-metadata">

**Author:** [@rosssymons](https://discuss.elastic.co/u/rosssymons)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 1:32pm UTC](https://discuss.elastic.co/t/office-365-logs-struggling-to-get-data-in/308015 "2022-06-23T13:32:01Z")

</div>

I've configured the Office 365 Logs integration but I'm struggling to get the data in. In my logs I'm seeing these lines: I'm not sure what 'currently in use, waiting...' is in reference to. I think all my config is…

---

## [Enable debug logging on metricbeat using a docker CMD](https://discuss.elastic.co/t/enable-debug-logging-on-metricbeat-using-a-docker-cmd/308006)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 1\
**Last updated:** [June 23, 2022, 1:07pm UTC](https://discuss.elastic.co/t/enable-debug-logging-on-metricbeat-using-a-docker-cmd/308006 "2022-06-23T13:07:40Z")

</div>

If I'm running metricbeat in docker, how can I enable debug logging? So far I've tried ./metricbeat setup -E logging.level="debug" && ./metricbeat ./metricbeat -d "\*" but I can't get it to work. I'm expecting the lo…

---

## [Filebeat in HA through active passive](https://discuss.elastic.co/t/filebeat-in-ha-through-active-passive/306987)

<div class="topic-metadata">

**Author:** [@diptesh2007](https://discuss.elastic.co/u/diptesh2007)\
**Replies:** 3\
**Last updated:** [June 23, 2022, 10:18am UTC](https://discuss.elastic.co/t/filebeat-in-ha-through-active-passive/306987 "2022-06-23T10:18:14Z")

</div>

I have a requirement to model ELK stack with failover across multiple AWS region. While there are no issues with running multiple instances of Logstash and Elasticsearch in active/active mode, the filebeat is expected t…

---

## [Filebeat configuration](https://discuss.elastic.co/t/filebeat-configuration/307974)

<div class="topic-metadata">

**Author:** [@Ronald1](https://discuss.elastic.co/u/Ronald1)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 9:28am UTC](https://discuss.elastic.co/t/filebeat-configuration/307974 "2022-06-23T09:28:25Z")

</div>

Hello all, This week I started looking into ELK to monitor our K8s cluster. Sorry if this is a newbie question :slight\_smile: I installed ELK (Elastic and Kibana) on a separate VM (not running on K8s) using Docker Comp…

---

## [Winlogbeat Kibana data not showing](https://discuss.elastic.co/t/winlogbeat-kibana-data-not-showing/307966)

<div class="topic-metadata">

**Author:** [@yhk](https://discuss.elastic.co/u/yhk)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 8:36am UTC](https://discuss.elastic.co/t/winlogbeat-kibana-data-not-showing/307966 "2022-06-23T08:36:46Z")

</div>

Hello I'm just studying ELK I have finished building the ELK environment. I'm testing to collect windows log through winlogbeat for the first time. However, the winlogbeat setup seems to have been completed normally, …

---

## [Filebeat not shipping logs to elasticsearch](https://discuss.elastic.co/t/filebeat-not-shipping-logs-to-elasticsearch/307783)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 3\
**Last updated:** [June 23, 2022, 6:04am UTC](https://discuss.elastic.co/t/filebeat-not-shipping-logs-to-elasticsearch/307783 "2022-06-23T06:04:01Z")

</div>

Hi Team, I am using Filebeat 8.0.0 And using filestream type for harvesting logs from 6 different paths with ingest pipeline. But i have to restart the Filebeat service to get the logs as it is not sending logs from t…

---

## [How to configure filebeat for AD logs in Cloudwatch](https://discuss.elastic.co/t/how-to-configure-filebeat-for-ad-logs-in-cloudwatch/307690)

<div class="topic-metadata">

**Author:** [@johnstancox](https://discuss.elastic.co/u/johnstancox)\
**Replies:** 3\
**Last updated:** [June 23, 2022, 6:03am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-for-ad-logs-in-cloudwatch/307690 "2022-06-23T06:03:01Z")

</div>

Hello Elastic/Beat super heroes, I am using filebeat to pull aws cloudwatch logs for an aws Active Directory service. So, the "message" property of the cloudwatch log record is the Windows Event log record. I would like…

---

## [Winlogbeat still creates default index when setting up to use a custom index](https://discuss.elastic.co/t/winlogbeat-still-creates-default-index-when-setting-up-to-use-a-custom-index/307905)

<div class="topic-metadata">

**Author:** [@Ryan\_Clark](https://discuss.elastic.co/u/Ryan_Clark)\
**Replies:** 0\
**Last updated:** [June 22, 2022, 5:23pm UTC](https://discuss.elastic.co/t/winlogbeat-still-creates-default-index-when-setting-up-to-use-a-custom-index/307905 "2022-06-22T17:23:48Z")

</div>

I'm trying to have winlogbeat write to a custom index. I've pre-configured the template, lifecycle policy, and initial index with alias. Using the instructions here (without the date agent version) doesn't work. It ignor…

---

## [ERROR metrics/metrics.go:376 error getting cgroup stats: error fetching stats for controller io: error fetching IO stats: error fetching io.pressure for path /sys/fs/cgroup:: open /sys/fs/cgroup/io.pressure: no such file or directory](https://discuss.elastic.co/t/error-metrics-metrics-go-376-error-getting-cgroup-stats-error-fetching-stats-for-controller-io-error-fetching-io-stats-error-fetching-io-pressure-for-path-sys-fs-cgroup-open-sys-fs-cgroup-io-pressure-no-such-file-or-directory/307804)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 2\
**Last updated:** [June 22, 2022, 2:51pm UTC](https://discuss.elastic.co/t/error-metrics-metrics-go-376-error-getting-cgroup-stats-error-fetching-stats-for-controller-io-error-fetching-io-stats-error-fetching-io-pressure-for-path-sys-fs-cgroup-open-sys-fs-cgroup-io-pressure-no-such-file-or-directory/307804 "2022-06-22T14:51:21Z")

</div>

Hello World! I'm following Run Filebeat on Docker | Filebeat Reference \[7.17\] | Elastic, yet seeing following ERROR in my logs (over and over): filebeat | 2022-06-21T21:08:17.932Z ERROR metrics/metrics.go:376 er…

---

## [Alert when data is missing?](https://discuss.elastic.co/t/alert-when-data-is-missing/307886)

<div class="topic-metadata">

**Author:** [@LionsELK](https://discuss.elastic.co/u/LionsELK)\
**Replies:** 3\
**Last updated:** [June 22, 2022, 2:07pm UTC](https://discuss.elastic.co/t/alert-when-data-is-missing/307886 "2022-06-22T14:07:13Z")

</div>

Hi all, Is there some form of functionality built into the ELK stack that can automatically alert me when data is missing? i.e. if we're missing a chunk of time like the image below. Currently, we're only made aware…

---

## [Filebeat system pipeline setup fails](https://discuss.elastic.co/t/filebeat-system-pipeline-setup-fails/307872)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 0\
**Last updated:** [June 22, 2022, 11:30am UTC](https://discuss.elastic.co/t/filebeat-system-pipeline-setup-fails/307872 "2022-06-22T11:30:18Z")

</div>

I've enabled the system module, enabled syslog and auth in system.yml. Yet for some reason I still get this error: $ sudo filebeat setup --pipelines --modules system Exiting: module system is configured but has no enabl…

---

## [Filebeat writting on 2 different indices](https://discuss.elastic.co/t/filebeat-writting-on-2-different-indices/307859)

<div class="topic-metadata">

**Author:** [@Elie\_Sbat](https://discuss.elastic.co/u/Elie_Sbat)\
**Replies:** 0\
**Last updated:** [June 22, 2022, 9:49am UTC](https://discuss.elastic.co/t/filebeat-writting-on-2-different-indices/307859 "2022-06-22T09:49:00Z")

</div>

Hello, I am ELK cluster v8 with filebeat v8.1.0 ot ship application logs. I have 2 different indices one for proxy and the other for owa. The name of the indices are: filebeat-8.1.0 for proxy logs filebeat-8.1.0-owa…

---

## [Notification for unenrollment](https://discuss.elastic.co/t/notification-for-unenrollment/307828)

<div class="topic-metadata">

**Author:** [@jongpil.won](https://discuss.elastic.co/u/jongpil.won)\
**Replies:** 0\
**Last updated:** [June 22, 2022, 5:03am UTC](https://discuss.elastic.co/t/notification-for-unenrollment/307828 "2022-06-22T05:03:18Z")

</div>

Unenrollment can be automatically performed through the unenrollment timeout setting in the Fleet UI, so can I get a notification for the event where the unenrollment operates? I'd like to set the result of automaticall…

---

## [How to retrieve data aws Lambda](https://discuss.elastic.co/t/how-to-retrieve-data-aws-lambda/307781)

<div class="topic-metadata">

**Author:** [@Renato\_Souza](https://discuss.elastic.co/u/Renato_Souza)\
**Replies:** 0\
**Last updated:** [June 21, 2022, 4:23pm UTC](https://discuss.elastic.co/t/how-to-retrieve-data-aws-lambda/307781 "2022-06-21T16:23:37Z")

</div>

How to retrieve data from AWS Lambda. I'm using functionbeat, but even with SAR I only retrieve CloudWatch logs as well. I would like support to know how to use these elastic integrations with AWS and I was able to dire…

---

## [Elastic Agent with fleet policy refuses to start properly](https://discuss.elastic.co/t/elastic-agent-with-fleet-policy-refuses-to-start-properly/307700)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 1\
**Last updated:** [June 21, 2022, 6:14pm UTC](https://discuss.elastic.co/t/elastic-agent-with-fleet-policy-refuses-to-start-properly/307700 "2022-06-21T18:14:54Z")

</div>

My Elastic Agent that runs the Fleet policy stopped working a week or two ago. As it cannot start the Fleet server. # elastic-agent status Status: FAILED Message: (no message) Applications: \* filebeat (C…

---

## [Azure Availability not showing on any event](https://discuss.elastic.co/t/azure-availability-not-showing-on-any-event/307790)

<div class="topic-metadata">

**Author:** [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Replies:** 0\
**Last updated:** [June 21, 2022, 6:06pm UTC](https://discuss.elastic.co/t/azure-availability-not-showing-on-any-event/307790 "2022-06-21T18:06:52Z")

</div>

Hey guys, I have a metricbeat that is collecting metrics from azure, like for example, databases and storage accounts. It is working fine, but i would like to create an alert to check when a database is down, but unfort…

---

## [No matching index template found for data streamd](https://discuss.elastic.co/t/no-matching-index-template-found-for-data-streamd/307485)

<div class="topic-metadata">

**Author:** [@Maksym\_Postument](https://discuss.elastic.co/u/Maksym_Postument)\
**Replies:** 2\
**Last updated:** [June 21, 2022, 8:29am UTC](https://discuss.elastic.co/t/no-matching-index-template-found-for-data-streamd/307485 "2022-06-21T08:29:47Z")

</div>

Hello, i am trying to run metricbeat setup command to create datastream but i am getting an error ./metricbeat setup --index-management -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=\["https://${ES\_URL}…

---

## [Discarding logs in elk](https://discuss.elastic.co/t/discarding-logs-in-elk/307481)

<div class="topic-metadata">

**Author:** [@ashisharyan](https://discuss.elastic.co/u/ashisharyan)\
**Replies:** 7\
**Last updated:** [June 21, 2022, 3:28am UTC](https://discuss.elastic.co/t/discarding-logs-in-elk/307481 "2022-06-21T03:28:33Z")

</div>

We are using winlogbeat agent. Can we discard or drop log messages based on a criteria defined in elk stack. We dont want to drop logs based on winlog yml config on systems but we want to drop logs centrally.Is it pos…

---

## [Filebeat file\_identity inode\_uuid](https://discuss.elastic.co/t/filebeat-file-identity-inode-uuid/307665)

<div class="topic-metadata">

**Author:** [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Replies:** 0\
**Last updated:** [June 20, 2022, 2:01pm UTC](https://discuss.elastic.co/t/filebeat-file-identity-inode-uuid/307665 "2022-06-20T14:01:57Z")

</div>

This may be an old discussion and we have seen some improvements in the past, but I would like to bring it up again. The issue is that by default, filebeat indentifies files by inode and device id. The problem with the …

---

## [Filter hosts based on port](https://discuss.elastic.co/t/filter-hosts-based-on-port/307495)

<div class="topic-metadata">

**Author:** [@Maksym\_Postument](https://discuss.elastic.co/u/Maksym_Postument)\
**Replies:** 1\
**Last updated:** [June 20, 2022, 12:27pm UTC](https://discuss.elastic.co/t/filter-hosts-based-on-port/307495 "2022-06-20T12:27:00Z")

</div>

Hello, i am using auto discovery in kubernetes and some discovered hosts has port 0 on which health check is failing. I want to be able to filter those hosts and run icmp check for them. How can i achieve this with condi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=84)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=86)
